Fortra Globalscape EFT's administration server suffers from an information disclosure vulnerability where the serial number of the harddrive that Globalscape is installed on can be remotely determined via a "trial extension request" message
References
Configurations
History
21 Nov 2024, 07:59
Type | Values Removed | Values Added |
---|---|---|
References | () https://kb.globalscape.com/Knowledgebase/11589/Is-EFT-susceptible-to-the-Remotely-obtain-HDD-serial-number-vulnerability - Vendor Advisory | |
References | () https://www.rapid7.com/blog/post/2023/06/22/multiple-vulnerabilities-in-fortra-globalscape-eft-administration-server-fixed/ - Exploit, Third Party Advisory |
30 Jun 2023, 19:28
Type | Values Removed | Values Added |
---|---|---|
CWE | NVD-CWE-noinfo | |
First Time |
Globalscape
Globalscape eft Server |
|
CPE | cpe:2.3:a:globalscape:eft_server:*:*:*:*:*:*:*:* | |
References | (MISC) https://www.rapid7.com/blog/post/2023/06/22/multiple-vulnerabilities-in-fortra-globalscape-eft-administration-server-fixed/ - Exploit, Third Party Advisory | |
References | (MISC) https://kb.globalscape.com/Knowledgebase/11589/Is-EFT-susceptible-to-the-Remotely-obtain-HDD-serial-number-vulnerability - Vendor Advisory | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.3 |
22 Jun 2023, 20:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-06-22 20:15
Updated : 2024-11-21 07:59
NVD link : CVE-2023-2991
Mitre link : CVE-2023-2991
CVE.ORG link : CVE-2023-2991
JSON object : View
Products Affected
globalscape
- eft_server
CWE